![Mastering Identity and Access Management with Microsoft Azure](https://wfqqreader-1252317822.image.myqcloud.com/cover/884/36698884/b_36698884.jpg)
Identity and password-hash synchronization including ADFS integration
With the implementation of the federation, all authentication is retained on-premises, and all passwords are stored on-premises only. All authentication traffic is redirected from Azure AD to the on-premises ADFS, which authenticates the user against a trusted AD domain. This scenario is commonly used in different company sizes if SSO is required and password-hash synchronization is prohibited due to \ security reasons.
The requirement is the usage of a federation service provider, such as ADFS in addition to Azure AD Connect in a highly available deployment.
The following diagram shows the identity and password-hash synchronization with ADFS scenario:
![](https://epubservercos.yuewen.com/1A2C27/19470381808825406/epubprivate/OEBPS/Images/c1ca8d1e-f95c-46e4-83c7-eb4f3a9d7eb4.png?sign=1738869804-QDrjKWQV9zw55gcVDFHKxU80WWdyCIUE-0-a6f27ed1024404b7fa7039cb3ade7f1e)
You can also combine the ADFS integration with password-hash synchronization to provide the capability if the on-premises infrastructure turns into an outage and users can still access their cloud services with their known password.